Oracle world shows a gap: EFI quantum states can exist without one-way puzzles
This paper builds a carefully constructed hypothetical world — a classical oracle — in which two leading assumptions for quantum cryptography come apart. EFI pairs are two quantum states that are easy to prepare, are very different in a statistical sense, but no efficient procedure can tell them apart. One-way puzzles are ordinary (classical) puzzles that are easy to make but hard to solve. In the real world one-way puzzles imply EFI pairs, and it was unknown whether the converse holds. The authors show that, relative to their oracle, one-way puzzles do not exist while an EFI pair still survives many kinds of attacks.
How did they do it? The oracle answers questions about the output probabilities of quantum samplers and at the same time hides a randomly chosen subspace of half the dimension (a “Haar-random half-dimensional subspace”). Because the oracle can report exact output probabilities, any classical construction of one-way puzzles is destroyed. At the same time the authors embed two quantum states whose indistinguishability resists every distinguisher that only queries the oracle with classical queries during its run, even if the distinguisher holds arbitrary advice derived from the oracle, and even if it is allowed a single quantum (superposition) query at the end.
To prove the EFI pair remains secure they reduce the problem to communication complexity. Informally, an adversary whose knowledge about the hidden subspace comes only through classical oracle answers can be simulated inside a two-party communication task against the party that holds the subspace. That limits the adversary to at best the known classical performance for the Vector-in-Subspace task (a lower-bound result of Klartag and Regev). The one quantum query at the end is handled separately with tools from random matrix theory. Together these arguments show no classical-queries adversary can distinguish the states, so the EFI pair survives in the oracle world.